Corero Network Security plc (LON:CNS) Chief Financial Officer Chris Goulden caught up with DirectorsTalk to discuss strong first-half 2026 performance, recent share-price volatility, cyber-resilience regulation, and the evolving DDoS threat landscape.
Q1: Chris, Corero Network Security recently published a half-year trading update. Could you just talk us through the highlights?
A1: As you mentioned, two weeks ago we issued a trading update on our first half of 2026 results, including some of the financial highlights.
We’re particularly pleased with the results in the first half of 2026, building on the sales momentum that we generated through the second half of 2025.
Combining last year’s strong ARR growth with good bookings uptick in the first half of the year, bookings being up 14%. Revenue was actually up 42% in the six-month period versus the same period in 2025. ARR continues to grow nicely year over year, that was up 12%. We maintained a strong gross margin; typically we’ve been running at about 90% in the period, we were 93%. This is the software-led nature of our solution.
I guess maybe one of the most impressive statistics in there is EBITDA. We saw a $4 million improvement on EBITDA in the period, from a $1.4 million loss in 2025 to a $2.6 million profit in 2026.
Additionally, we had a notable contract post-period end with a globally recognised Tier-1 telco provider in the U.S., actually a big name that most people would recognise. This really is recognition and validation of the go-to-market refresh and particularly the kind of product innovation strategy that Carl, our CEO, put in place.
In 2025, we developed and we released six new products. This increased our competitiveness and kept us in tenders, particularly with these larger customers who require a more diverse solution set. This recognition that we’re now selling into theTier-1 global community, these are the largest, most complex, most discerning customers.
So, we’re really pleased that our solution has been validated in this arena, and we hope this is the first of many in that region.
Q2: Corero’s share price has been quite volatile post-trading update, are you able to shed any light on the activity?
A2: The morning after the trading update was released, we saw an initial really positive response and the share price was up around 20% through morning trading. By the end of the day, that fell back to a small gain. Sometimes this happens as people take profit through the day but generally a good reaction on the day to the trading update.
Subsequent to the trading update, we have been made aware of a recent change in ownership and a sell-off of the new owner’s stake. That’s had a negative impact on the share price subsequently to the trading update.
Q3: Several investors have discussed the fact that a significant shareholder has recently talked of activism and has been forced to sell their holding in Corero. As much as you can, are you able to comment on that?
A3: The Saba strategy to take significant holdings in a number of UK funds has been well publicised and one of our long-term holders, Herald, were one of those funds that Saba took that strategy on. As a consequence of that, Saba effectively acquired a significant holding in Corero.
As I said, we don’t believe the Saba strategy is to hold individual positions in small caps such as Corero.
Q4: Now, with increasing legislation around cyber resilience in the UK and globally, is that having an impact on your sales pipeline?
A4: Cyber security and technical security as a general industry has had longstanding regulations, but this is really the first time that those regulations have had a direct impact on DDoS specifically. Within that, we’re particularly looking at resiliency-type regulation and data sovereignty regulations.
So, in 2025, we announced that we won a contract with a major European bank off the back of the DORA Act in the EU, which was specifically around additional security and resiliency for financial services within the EU. We’re seeing also pipeline increase and opportunities from regulations such as the Cyber Security and Resilience Bill in the UK, and also the Telecom Security Act in the UK.
We’re seeing customers coming to us now because they have a need for a more substantial solution to meet these regulations.
So, the way that Corero meets and helps these customers is primarily our on-prem solution so it’s maintaining the customer data on their network, in their location. That helps them primarily to meet these data sovereignty and resiliency requirements.
Q5: We’ve previously discussed the threat landscape around cyber-attacks, specifically DDoS. How do you think about that trend as we move towards the end of the year?
A5: We released our latest threat intelligence report at the start of the year, and we identified that DDoS attacks and the DDoS landscape are getting larger. They’re also getting faster and far more complex.
This is largely due to new tools and new specialisms available to those bad actors who rather than doing one-off smaller attacks, can now combine attacks and can increase the efficacy of these attacks through really easy-access tooling.
We’re seeing this and we’re hearing these examples and trends from our customers and partners and potential customers that we’re speaking to in the market.
Now, we recently announced that for the second year in a row, we were identified as the emerging innovator in the DDoS space by one of the leading industry analysts. This has reflected the fact that we believe, and we’ve been recognised as the organisation that is innovating in this space, really looking at new and more effective techniques to combat this evolving threat landscape.
We believe that we’re best placed in the market to support customers with this ever-growing, ever-evolving cyber resiliency threat and we’re seeing that coming through in our pipeline and we’re seeing that in the customer satisfaction and the customer retention scores that we continue to see in our financial results.



































